Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,049 matching · page 1092/1321Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-36563(opens NVD record) | Medium | 6.5 | Microsoft WordPad Information Disclosure Vulnerability | Oct 10, 2023 |
| CVE-2023-36561(opens NVD record) | High | 7.3 | Azure DevOps Server Elevation of Privilege Vulnerability | Oct 10, 2023 |
| CVE-2023-36557(opens NVD record) | High | 7.8 | PrintHTML API Remote Code Execution Vulnerability | Oct 10, 2023 |
| CVE-2023-36438(opens NVD record) | High | 7.5 | Windows TCP/IP Information Disclosure Vulnerability | Oct 10, 2023 |
| CVE-2023-36436(opens NVD record) | High | 7.8 | Windows MSHTML Platform Remote Code Execution Vulnerability | Oct 10, 2023 |
| CVE-2023-36435(opens NVD record) | High | 7.5 | Microsoft QUIC Denial of Service Vulnerability | Oct 10, 2023 |
| CVE-2023-36434(opens NVD record) | Critical | 9.8 | Windows IIS Server Elevation of Privilege Vulnerability | Oct 10, 2023 |
| CVE-2023-36433(opens NVD record) | Medium | 6.5 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | Oct 10, 2023 |
| CVE-2023-36431(opens NVD record) | High | 7.5 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Oct 10, 2023 |
| CVE-2023-36429(opens NVD record) | Medium | 6.5 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | Oct 10, 2023 |
| CVE-2023-36420(opens NVD record) | High | 7.8 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Oct 10, 2023 |
| CVE-2023-36419(opens NVD record) | High | 8.8 | Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability | Oct 10, 2023 |
| CVE-2023-36418(opens NVD record) | High | 7.8 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | Oct 10, 2023 |
| CVE-2023-36417(opens NVD record) | High | 7.8 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | Oct 10, 2023 |
| CVE-2023-36416(opens NVD record) | Medium | 6.1 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Oct 10, 2023 |
| CVE-2023-36415(opens NVD record) | High | 8.8 | Azure Identity SDK Remote Code Execution Vulnerability | Oct 10, 2023 |
| CVE-2023-36414(opens NVD record) | High | 8.8 | Azure Identity SDK Remote Code Execution Vulnerability | Oct 10, 2023 |
| CVE-2023-35349(opens NVD record) | Critical | 9.8 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Oct 10, 2023 |
| CVE-2023-29348(opens NVD record) | High | 7.5 | Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability | Oct 10, 2023 |
| CVE-2023-44249(opens NVD record) | Medium | 4.3 | An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests. | Oct 10, 2023 |
| CVE-2023-42788(opens NVD record) | High | 7.8 | An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command | Oct 10, 2023 |
| CVE-2023-42787(opens NVD record) | Medium | 6.5 | A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution. | Oct 10, 2023 |
| CVE-2023-42782(opens NVD record) | Medium | 5.3 | A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number. | Oct 10, 2023 |
| CVE-2023-41841(opens NVD record) | High | 8.1 | An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile to perform elevated actions. | Oct 10, 2023 |
| CVE-2023-41838(opens NVD record) | High | 7.1 | An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli. | Oct 10, 2023 |
| CVE-2023-41679(opens NVD record) | High | 8.5 | An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device management" permission on his profile and belonging to a specific ADOM to add and delete CLI script on other ADOMs | Oct 10, 2023 |
| CVE-2023-41675(opens NVD record) | Medium | 5.3 | A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection. | Oct 10, 2023 |
| CVE-2023-40718(opens NVD record) | High | 7.5 | A interpretation conflict in Fortinet IPS Engine versions 7.321, 7.166 and 6.158 allows attacker to evade IPS features via crafted TCP packets. | Oct 10, 2023 |
| CVE-2023-37939(opens NVD record) | Low | 3.3 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions, 6.2 all versions, may allow a local authenticated attacker with no Administrative privileges to retrieve the list of files or folders excluded from malware scanning. | Oct 10, 2023 |
| CVE-2023-37935(opens NVD record) | Medium | 6.5 | A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services. | Oct 10, 2023 |
| CVE-2023-36637(opens NVD record) | Low | 3.5 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields. | Oct 10, 2023 |
| CVE-2023-36556(opens NVD record) | High | 8.8 | An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests. | Oct 10, 2023 |
| CVE-2023-36555(opens NVD record) | Low | 3.9 | An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components. | Oct 10, 2023 |
| CVE-2023-36550(opens NVD record) | Critical | 9.8 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters. | Oct 10, 2023 |
| CVE-2023-36549(opens NVD record) | High | 8.8 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters. | Oct 10, 2023 |
| CVE-2023-36548(opens NVD record) | Critical | 9.8 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters. | Oct 10, 2023 |
| CVE-2023-36547(opens NVD record) | Critical | 9.8 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters. | Oct 10, 2023 |
| CVE-2023-34993(opens NVD record) | Critical | 9.8 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters. | Oct 10, 2023 |
| CVE-2023-34992(opens NVD record) | Critical | 10.0 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests. | Oct 10, 2023 |
| CVE-2023-34989(opens NVD record) | High | 8.8 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters. | Oct 10, 2023 |
| CVE-2023-34988(opens NVD record) | High | 8.8 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters. | Oct 10, 2023 |
| CVE-2023-34987(opens NVD record) | High | 8.8 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters. | Oct 10, 2023 |
| CVE-2023-34986(opens NVD record) | High | 8.8 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters. | Oct 10, 2023 |
| CVE-2023-34985(opens NVD record) | High | 8.8 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters. | Oct 10, 2023 |
| CVE-2023-33301(opens NVD record) | Medium | 6.5 | An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host. | Oct 10, 2023 |
| CVE-2023-25607(opens NVD record) | High | 7.8 | An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions, FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiADC 7.1.0, 7.0.0 through 7.0.3, 6.2 all versions, 6.1 all versions, 6.0 all versions management interface may allow an authenticated attacker with at least READ permissions on system settings to execute arbitrary commands on the underlying shell due to an unsafe usage of the wordexp function. | Oct 10, 2023 |
| CVE-2023-25604(opens NVD record) | Medium | 5.5 | An insertion of sensitive information into log file vulnerability in Fortinet FortiGuest 1.0.0 allows a local attacker to access plaintext passwords in the RADIUS logs. | Oct 10, 2023 |
| CVE-2022-22298(opens NVD record) | Medium | 6.7 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0.0, FortiIsolator version 1.1.0, FortiIsolator version 1.2.0 through 1.2.2, FortiIsolator version 2.0.0 through 2.0.1, FortiIsolator version 2.1.0 through 2.1.2, FortiIsolator version 2.2.0, FortiIsolator version 2.3.0 through 2.3.4 allows attacker to execute arbitrary OS commands in the underlying shell via specially crafted input parameters. | Oct 10, 2023 |
| CVE-2023-43896(opens NVD record) | High | 7.8 | A buffer overflow in Macrium Reflect 8.1.7544 and below allows attackers to escalate privileges or execute arbitrary code. | Oct 10, 2023 |
| CVE-2023-4966(opens NVD record) | Critical | 9.4 | Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | Oct 10, 2023 |